Verus Ethereum bridge exploited again, about $7.53 million moved to 0xCFd0 address

Verus Ethereum bridge exploited again, about $7.53 million moved to 0xCFd0 address

A fresh exploit drained roughly $7.3 million to $7.5 million from the same Verus bridge contract hit in May, with researchers saying the bridge still failed to verify that Ethereum payouts were economically backed on the Verus side.

ETH
USDT
USDC

Fact Check
The originating security firm CertiK Alert directly confirms all core facts: the Verus Ethereum bridge exploit, the ~$7.53M figure, the destination address beginning 0xCFd0, and the verification-gap root cause paralleling the May incident. PANews (which cites CertiK) and Phemex reproduce the same details. The reference to a prior ~$11.58M May loss is independently corroborated by memeburn and cryptotimes reporting. The claim's phrasing ('forged cross-chain proofs') aligns with the reported cause of a bridge failing to validate that Verus-side inputs back withdrawn amounts.
Summary

Verus’s Ethereum bridge was hit by another exploit on July 23, with blockchain security researchers estimating losses at roughly $7.3 million to $7.5 million in ETH and tokens drained from the same contract targeted in May. Researchers said the attacker used a maliciously crafted import from the Verus side to trigger Ethereum-side reserve payouts that were backed by valid notary signatures, state roots and Merkle proofs, but not by matching locked or exported assets on the source chain. Assets taken included Ether, tBTC, MKR, USDC, Tether, EURC and scrvUSD, while the bridge also interacted with a Sky collateral position to mint about 220,357 DAI to satisfy the fraudulent request. Backward Labs said the root cause was an authorization bypass and protocol-state assumption issue, and published a proof-of-concept describing a broken invariant in the bridge lifecycle checks. The firm said the same root cause had remained exploitable for 66 days. The incident was the second breach of the same contract and vulnerability in about two months after the May 17 attack that stole about $11.6 million, bringing cumulative losses to about $19.1 million. The repeat exploit underscores a familiar DeFi bridge risk: cryptographic proofs can validate correctly even when business-logic checks fail to confirm the payout is economically backed.

Terms & Concepts
  • Merkle proofs: Cryptographic proofs used to confirm that specific data is included in a larger dataset without revealing the entire dataset.
  • cross-chain bridges: Protocols that move assets or data between blockchains, typically by locking assets on one chain and releasing or minting them on another.
  • DAI: A dollar-pegged token minted against collateral in the Maker ecosystem, now branded as Sky.